NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84762 | CVE-2017-6919 | Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests. | 2 | 6 | Medium | 2017-07-18 | 2017-07-10 | View | |
86042 | CVE-2017-7661 | Apache CXF Fediz ships with a number of container-specific plugins to enable WS-Federation for applications. A CSRF (Cross Style Request Forgery) style vulnerability has been found in the Spring 2, Spring 3, Jetty 8 and Jetty 9 plugins in Apache CXF Fediz prior to 1.4.0, 1.3.2 and 1.2.4. | 2 | 6.8 | Medium | 2017-07-18 | 2017-07-07 | View | |
86554 | CVE-2016-10376 | Gajim through 0.16.7 unconditionally implements the XEP-0146: Remote Controlling Clients extension. This can be abused by malicious XMPP servers to, for example, extract plaintext from OTR encrypted sessions. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-10 | View | |
87578 | CVE-2017-1000039 | Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution | 2017-07-18 | 2017-07-17 | View | ||||
87834 | CVE-2017-11337 | There is an invalid free in the Action::TaskFactory::cleanup function of actions.cpp in Exiv2 0.26. A crafted input will lead to a remote denial of service attack. | 2017-07-18 | 2017-07-17 | View |
Page 16447 of 17672, showing 5 records out of 88360 total, starting on record 82231, ending on 82235